Allocation of Resources Without Limits or Throttling in Next.js - #VU130278
Published: May 6, 2026
Next.js
vercel
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the Image Optimization API when handling requests to the /_next/image endpoint for large local assets matching configured local patterns. A remote attacker can request large local assets to cause a denial of service.
Only self-hosted deployments using the default image loader are vulnerable. By default, all local patterns are allowed.